Skip to content

Commit c4acb00

Browse files
Sync EUVD catalog: Fri Jun 26 00:56:40 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 5507bb0 commit c4acb00

506 files changed

Lines changed: 33997 additions & 157 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2020-31260",
3+
"enisaUuid": "c217792e-0b88-3802-875c-64141515193b",
4+
"description": "Grav before 1.6.30 contains a cross-site scripting vulnerability in the Admin plugin page editor default security configuration. Privileged users with page editing capabilities can inject malicious scripts to execute arbitrary code and install malicious plugins for system access.",
5+
"datePublished": "Jun 25, 2026, 9:41:00 PM",
6+
"dateUpdated": "Jun 25, 2026, 9:41:00 PM",
7+
"baseScore": 5.1,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
10+
"references": "https://github.com/getgrav/grav/security/advisories/GHSA-cvmr-6428-87w9\nhttps://www.vulncheck.com/advisories/grav-cross-site-scripting-in-admin-plugin-page-editor\n",
11+
"aliases": "CVE-2020-37256\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "75a2a30b-4b78-372d-9071-62f3f59b0c03",
17+
"product": {
18+
"name": "grav",
19+
"vendor": {
20+
"name": "getgrav"
21+
}
22+
},
23+
"product_version": "0 <1.6.30"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "38d7bd30-eca4-30f2-8795-c6cb32423f1c",
29+
"vendor": {
30+
"name": "Grav"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2021-34852",
3+
"enisaUuid": "5aadcef7-209c-3c7e-bb9e-4d11de3039bb",
4+
"description": "Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed code in a personal fork. Attackers could exploit this by specifying affected version tags in dependency declarations to execute unreviewed and potentially malicious code.",
5+
"datePublished": "Jun 25, 2026, 9:41:01 PM",
6+
"dateUpdated": "Jun 25, 2026, 9:41:01 PM",
7+
"baseScore": 7.7,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
10+
"references": "https://github.com/parse-community/parse-server/security/advisories/GHSA-593v-wcqx-hq2w\nhttps://www.vulncheck.com/advisories/parse-server-unreviewed-code-execution-via-malicious-version-tags\n",
11+
"aliases": "CVE-2021-47986\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "3a3ad0f5-c626-3525-8015-7f1acb06dc25",
17+
"product": {
18+
"name": "parse-server",
19+
"vendor": {
20+
"name": "parse-community"
21+
}
22+
},
23+
"product_version": "0 <4.10.0"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "71bff8e9-d54b-3004-9cd9-43c53fa41a7e",
29+
"vendor": {
30+
"name": "parse-community"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2021-34853",
3+
"enisaUuid": "d48fdc73-cee0-3a30-af84-e7ba7b9ecda2",
4+
"description": "Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the official repository pointing to an unreviewed personal fork of a contributor with write access. No releases were published with these tags; a project was exposed only if it defined a git-based dependency referencing one of the affected tags (for example, parse-server#4.9.3). The code behind the tags was not reviewed or approved, and although no malicious code was identified, the introduction of security vulnerabilities could not be ruled out.",
5+
"datePublished": "Jun 25, 2026, 9:41:02 PM",
6+
"dateUpdated": "Jun 25, 2026, 9:41:02 PM",
7+
"baseScore": 7.7,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
10+
"references": "https://github.com/parse-community/parse-server/security/advisories/GHSA-593v-wcqx-hq2w\nhttps://www.vulncheck.com/advisories/parse-server-arbitrary-code-execution-via-malicious-version-tags\n",
11+
"aliases": "CVE-2021-47987\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "7fde52e9-092b-313d-bc7a-b7946b7486dc",
17+
"product": {
18+
"name": "parse-server",
19+
"vendor": {
20+
"name": "parse-community"
21+
}
22+
},
23+
"product_version": "0 <4.10.0"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "539185f2-29cd-39f7-946b-e956021a42c7",
29+
"vendor": {
30+
"name": "parse-community"
31+
}
32+
}
33+
]
34+
}
Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
{
2+
"id": "EUVD-2025-210330",
3+
"enisaUuid": "9e53cda2-8dd0-3284-8637-4e57814c7000",
4+
"description": "A use-after-free in the gf_filter_pid_get_packet function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted media file.",
5+
"datePublished": "Jun 25, 2026, 12:33:23 AM",
6+
"dateUpdated": "Jun 25, 2026, 12:33:23 AM",
7+
"baseScore": 0.0,
8+
"references": "https://github.com/gpac/gpac/issues/3284\nhttps://github.com/gpac/gpac/commit/4a7ea06dd1b2cc65fe0dabc60189eb6bc814f7bb\nhttps://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/35/35_gf_filter_pid_get_packet_filter_core_filter_pid_c_6827\nhttps://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/35/README.md\nhttps://infosec.exchange/@sigdevel/116780402249845037\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-60466\n",
9+
"aliases": "CVE-2025-60466\nGHSA-5jcp-h69w-6fg7\n",
10+
"assigner": "mitre",
11+
"epss": 0.0,
12+
"enisaIdProduct": [
13+
{
14+
"id": "b4e58b62-f404-3371-a042-b68757b76290",
15+
"product": {
16+
"name": "n/a",
17+
"vendor": {
18+
"name": "n/a"
19+
}
20+
},
21+
"product_version": "n/a"
22+
}
23+
],
24+
"enisaIdVendor": [
25+
{
26+
"id": "fc24aa3d-3607-38b3-bdbc-a826abef546c",
27+
"vendor": {
28+
"name": "n/a"
29+
}
30+
}
31+
]
32+
}
Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
{
2+
"id": "EUVD-2025-210331",
3+
"enisaUuid": "65fbc0f9-38ad-3d1a-97e0-8b75eda5cb5a",
4+
"description": "A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted media file.",
5+
"datePublished": "Jun 25, 2026, 12:33:23 AM",
6+
"dateUpdated": "Jun 25, 2026, 12:33:23 AM",
7+
"baseScore": 0.0,
8+
"references": "https://github.com/gpac/gpac/issues/3286\nhttps://github.com/gpac/gpac/commit/976dacf65cb6986a4e4f350fb8d3ed0a17dc3a77\nhttps://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/37/37_gf_filter_pid_inst_swap_delete_task_filter_core_filter_pid_c_574\nhttps://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/37/README.md\nhttps://infosec.exchange/@sigdevel/116780518074911144\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-60467\n",
9+
"aliases": "GHSA-3q4w-vhww-wccf\nCVE-2025-60467\n",
10+
"assigner": "mitre",
11+
"epss": 0.0,
12+
"enisaIdProduct": [
13+
{
14+
"id": "71b088e7-bcd1-32e1-81c0-1bdd704f0533",
15+
"product": {
16+
"name": "n/a",
17+
"vendor": {
18+
"name": "n/a"
19+
}
20+
},
21+
"product_version": "n/a"
22+
}
23+
],
24+
"enisaIdVendor": [
25+
{
26+
"id": "97869902-c9db-3a55-a096-508d128f00fa",
27+
"vendor": {
28+
"name": "n/a"
29+
}
30+
}
31+
]
32+
}
Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
{
2+
"id": "EUVD-2025-210332",
3+
"enisaUuid": "d58e3eda-c6a1-3761-98af-f1e05bbad41f",
4+
"description": "GPAC Multimedia Open Source Project GPAC Project/MP4Box 2.5-DEV-rev1593-gfe88c3545-master is affected by: Buffer Overflow. The impact is: cause a denial of service (local). The component is: filter_core/filter_pid.c (L:574-580): function gf_filter_pid_inst_swap_delete_task() improperly accesses freed objects during PID instance swap/delete cleanup, leading to heap use-after-free. The attack vector is: Local (AV:L): a local, authenticated user who processes a specially crafted MPEG-2 TS/MP4 file with MP4Box can trigger the bug during filter teardown (PID instance swap/delete), causing a crash. \u00b6\u00b6 In GPAC s MP4Box, gf_filter_pid_inst_swap_delete_task() in filter_core/filter_pid.c may dereference objects after they have been freed when cleaning up PID instances after a swap/delete operation. Crafted inputs (e.g., malformed MPEG-2 TS) can trigger a heap use-after-free and crash; exploitation may be possible.",
5+
"datePublished": "Jun 25, 2026, 12:33:21 AM",
6+
"dateUpdated": "Jun 25, 2026, 12:33:22 AM",
7+
"baseScore": 0.0,
8+
"references": "https://github.com/gpac/gpac/commit/976dacf65cb6986a4e4f350fb8d3ed0a17dc3a77\nhttps://github.com/gpac/gpac/issues/3290\nhttps://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/39/39_gf_filter_pid_inst_swap_delete_task_filter_core_filter_pid_c_580\nhttps://github.com/gpac/gpac/commit/aed9c94e92e8ba362ddb29c767c519478f46f195\nhttps://infosec.exchange/@sigdevel/116780598378458041\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-60468\n",
9+
"aliases": "CVE-2025-60468\nGHSA-fj4j-92hj-mcwp\n",
10+
"assigner": "mitre",
11+
"epss": 0.0,
12+
"enisaIdProduct": [
13+
{
14+
"id": "ce814576-c398-3a12-8ff8-5036702bd4e6",
15+
"product": {
16+
"name": "n/a",
17+
"vendor": {
18+
"name": "n/a"
19+
}
20+
},
21+
"product_version": "n/a"
22+
}
23+
],
24+
"enisaIdVendor": [
25+
{
26+
"id": "fc918a93-7c09-3c85-9aa1-63754428798b",
27+
"vendor": {
28+
"name": "n/a"
29+
}
30+
}
31+
]
32+
}
Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
{
2+
"id": "EUVD-2025-210334",
3+
"enisaUuid": "29287365-c05c-345d-960c-612f5cdc002d",
4+
"description": "A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.",
5+
"datePublished": "Jun 25, 2026, 12:33:23 AM",
6+
"dateUpdated": "Jun 25, 2026, 12:33:23 AM",
7+
"baseScore": 0.0,
8+
"references": "https://github.com/gpac/gpac/issues/3285\nhttps://github.com/gpac/gpac/commit/b8d80b44718de10b101e1d7fc17c84d69feb092e\nhttps://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/36/README.md\nhttps://infosec.exchange/@sigdevel/116780471059317580\nhttps://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/36/36_gf_filter_in_parent_chain_filter_core_filter_pid_c_2145\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-60473\n",
9+
"aliases": "CVE-2025-60473\nGHSA-8hg9-39h6-3rjm\n",
10+
"assigner": "mitre",
11+
"epss": 0.0,
12+
"enisaIdProduct": [
13+
{
14+
"id": "55b428ea-777e-3cb3-af32-69e94180270e",
15+
"product": {
16+
"name": "n/a",
17+
"vendor": {
18+
"name": "n/a"
19+
}
20+
},
21+
"product_version": "n/a"
22+
}
23+
],
24+
"enisaIdVendor": [
25+
{
26+
"id": "1d565e1f-52e5-34b0-80bb-ecd29703649a",
27+
"vendor": {
28+
"name": "n/a"
29+
}
30+
}
31+
]
32+
}
Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
{
2+
"id": "EUVD-2025-210335",
3+
"enisaUuid": "7d620e3c-3315-36a8-af41-019f2f987eb6",
4+
"description": "A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.",
5+
"datePublished": "Jun 25, 2026, 12:33:23 AM",
6+
"dateUpdated": "Jun 25, 2026, 12:33:23 AM",
7+
"baseScore": 0.0,
8+
"references": "https://github.com/gpac/gpac/issues/3287\nhttps://github.com/gpac/gpac/commit/bd7fd6be546e0cd9e599c6b262c338c5f2ecec5c\nhttps://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/38/38_gf_media_import_media_tools_media_import_c_1297\nhttps://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/38/README.md\nhttps://infosec.exchange/@sigdevel/116780566799952592\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-60474\n",
9+
"aliases": "GHSA-cqcc-c9q9-x82m\nCVE-2025-60474\n",
10+
"assigner": "mitre",
11+
"epss": 0.0,
12+
"enisaIdProduct": [
13+
{
14+
"id": "7c840773-bdb5-3989-8590-68c0de2bd897",
15+
"product": {
16+
"name": "n/a",
17+
"vendor": {
18+
"name": "n/a"
19+
}
20+
},
21+
"product_version": "n/a"
22+
}
23+
],
24+
"enisaIdVendor": [
25+
{
26+
"id": "39041230-7670-3825-a022-099c7e41799f",
27+
"vendor": {
28+
"name": "n/a"
29+
}
30+
}
31+
]
32+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2025-210336",
3+
"enisaUuid": "ee184712-db48-3f2a-a9af-07e26db9e5a9",
4+
"description": "Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-file and /api/v1/openai-assistants-file/download endpoints. The chatId value is not validated and is passed to streamStorageFile(), where a fallback file-lookup path constructed without the orgId is evaluated after the storage-directory containment check, allowing path traversal beyond the intended storage directory. Unauthenticated attackers can read sensitive files such as /root/.flowise/database.sqlite, exposing all database content in the default configuration.",
5+
"datePublished": "Jun 25, 2026, 9:41:02 PM",
6+
"dateUpdated": "Jun 25, 2026, 9:41:02 PM",
7+
"baseScore": 8.7,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-99pg-hqvx-r4gf\nhttps://www.vulncheck.com/advisories/flowise-arbitrary-file-read-via-chatid-parameter\n",
11+
"aliases": "CVE-2025-71324\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "102f7e9c-6b46-3848-ba47-9c8b178bb932",
17+
"product": {
18+
"name": "Flowise",
19+
"vendor": {
20+
"name": "FlowiseAI"
21+
}
22+
},
23+
"product_version": "0 <3.0.6"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "d714638a-0d47-3a6d-bf00-a87e8cbe1fd4",
29+
"vendor": {
30+
"name": "Flowise"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2025-210337",
3+
"enisaUuid": "68c08833-c88d-3b5e-8b02-3d39b387dc9e",
4+
"description": "Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to create user accounts. Remote attackers can exploit this endpoint to register arbitrary accounts and authenticate to the system, gaining full API access without credentials.",
5+
"datePublished": "Jun 25, 2026, 9:41:03 PM",
6+
"dateUpdated": "Jun 25, 2026, 9:41:03 PM",
7+
"baseScore": 9.3,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
10+
"references": "https://github.com/FlowiseAI/Flowise/security/advisories/GHSA-v5w9-prxf-w882\nhttps://www.vulncheck.com/advisories/flowise-authentication-bypass-via-unprotected-registration-endpoint\n",
11+
"aliases": "CVE-2025-71327\n",
12+
"assigner": "VulnCheck",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "e0ac1751-39ec-3009-b10d-644f4bb59ef2",
17+
"product": {
18+
"name": "Flowise",
19+
"vendor": {
20+
"name": "FlowiseAI"
21+
}
22+
},
23+
"product_version": "3.0.1"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "7e8953a4-e0a0-315e-bbf9-d9e8979d566c",
29+
"vendor": {
30+
"name": "Flowise"
31+
}
32+
}
33+
]
34+
}

0 commit comments

Comments
 (0)